Solved

What to do with the gateway when implenting a HP5406zl switch with Vlan routing

Posted on 2013-05-29
4
463 Views
Last Modified: 2013-06-06
Hi,

we've just bought a HP 5406zl witch we will use as a router between our internal networks.
At the moment we use a Juniper SRX firewall to do the routing (no policies exist internal)
I have a "simple" question ;-)
I know we can setup the HP5406zl as a router between the Vlans but do we have to change the gateway on the network where the firewall is placed to the HP5406zl or can we keep our firewall ipaddress as the gateway? (I suppose not, but I wan't to be sure)

The pc's are on the 10.0.0.0/22 network with 10.0.0.1 as gateway, the networks 10.0.5.0/24, 10.0.8.0/24 and 10.0.10.0/24, have all a gateway on the firewall (all on a separate interface).
So for the networks 10.0.5.0/24, 10.0.8.0/24 and 10.0.10.0/24 I can create a Vlan with the same ip as the actual gateway, I suppose I just add a route on those gateways to 10.0.0.1, (the firewall gateway to the internet) and if needed a ACL to block a some Vlan's to access some other if needed. But the 10.0.0.0/22 uses the firewall as the gateway 10.0.0.1 so what do I do with this gateway?
Do I create a Vlan with ip 10.0.0.2 and use that as the gateway on the pc's? And then add a route on the switch to go to the internet via 10.0.0.1?

I hope someone can help me on setting up this switch ;-)
0
Comment
Question by:heensit
  • 2
4 Comments
 
LVL 17

Accepted Solution

by:
jburgaard earned 350 total points
ID: 39206052
I do not know how easy it is to change settings on a Juniper SRX firewall, but what springs to my mind is:
As I read your Q, you want to move  A L L  internal routing to HP 5406zl, operating as L3-switch. So move ALL internal vlan-IP's to this (including 10.0.0.1) .
Keep clients as they are.
Between FW and L3 make a transport-vlan.
So on FW set internal IP: 192.168.99.1
On L3 make transport-vlan with IP 192.168.99.2
on FW make an:       ip route 10.0.0.0  255.0.0.0  192.168.99.2
on L3 make a dgw:   ip route 0.0.0.0  0.0.0.0  192.168.99.1

HTH
0
 
LVL 2

Author Comment

by:heensit
ID: 39206861
looks like a good plan ;-) but we are using our firewall to do natting (citrix/mail/http) wouldn't that give a problem if the 10.0.0.0/22 subnet is no longer on the firewall.
I always thought that the subnet of the ipaddresses where you want to forward to needed to be on one of the interfaces...
0
 

Assisted Solution

by:TFortson514
TFortson514 earned 150 total points
ID: 39211930
jburs plan is solid.  You would just need to make sure that the firewall knows how to get to the 10 subnet for nating purposes... ie static route or participating in routing.
0
 
LVL 2

Author Closing Comment

by:heensit
ID: 39226884
Hi,

tnx the migration didn't go totally smooth, but after eliminating some minor error it seems to work fine...
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now